Last updated: April 2026
1. Introduction
Beyond Reality ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our website and application. We believe in full transparency. This policy is written to be as clear and specific as possible about what data we collect, why, and how it is handled.
2. Information we collect
Information you provide
- Account information: Email address, name, and profile details when you create an account
- Journal entries: Content you write in your journal
- Goals and reflections: Goals you set and your responses to reflection prompts
- Personality test results: Scores, traits, and insights from personality assessments you complete or create
- Payment information: Processed securely through Mollie; we do not store credit card numbers
Information collected automatically
- Push notification tokens: Collected when you enable notifications, used solely to deliver notifications to your device
3. How we use your information
- To provide and improve our services
- To process payments and manage subscriptions
- To communicate with you about your account and updates
- To ensure the security and integrity of our platform
- To provide AI-powered features such as goal improvement suggestions, reflection generation, and Virtual Buddy interactions
- To generate journal embeddings. Your journal text is transformed into numerical vectors (mathematical representations, not readable text) to enable content-based features
4. Data storage and security
Your data is stored in Google Firebase, protected by Google Cloud's infrastructure encryption: AES-256 encryption at rest and TLS encryption in transit. We use Firebase Security Rules to enforce ownership-based access control, ensuring users can only access their own data (and data explicitly shared with them).
Database administrators have technical access to the Firebase infrastructure. We maintain strict internal policies ensuring personal data is only accessed when necessary for service operation or support.
5. Data sharing
We do not sell your personal data. We only share data with the following third-party processors:
- Google Firebase: Infrastructure, authentication, and data storage
- Mollie: Payment processing (EU-based, data stays within the EEA)
- Anthropic: Primary AI processing (goal improvement, reflection generation, Virtual Buddy responses). When you use these features, relevant content such as journal entries, goal text, personality traits, and themes is sent to Anthropic's API. Anthropic does not use API data for model training
- OpenAI: Journal embedding generation only. Journal text is transformed into numerical vectors (embeddings) that are not human-readable and reduce direct exposure of your text. These embeddings are stored alongside the original content on the same records and are subject to the same data protection policies. API data is not used for model training (Beyond Reality has not opted in). OpenAI may retain abuse monitoring logs for up to 30 days
We have Data Processing Agreements (DPAs) in place with our processors to ensure your data is handled in compliance with GDPR.
Accountability buddies
You can choose to share specific records (such as goals, journal entries, reviews, personality tests, and themes) with other users ("accountability buddies"). All sharing is explicit and user-initiated: you control exactly what records are shared and with whom. Buddies have read-only access to your shared records and can leave comments on them. You can revoke sharing at any time.
Virtual Buddies (AI companions)
Virtual Buddies are AI-powered companions that can observe and respond to your shared records. No data is sent for Virtual Buddy processing unless you explicitly add a Virtual Buddy to your shared list.
When a Virtual Buddy is active, it receives: the shared record content (e.g., a goal or journal entry), your personality test insights, your selected themes, and recent comment history. This data is sent to Anthropic for generating a response. Daily caps and cooldown periods limit the frequency of AI processing per Virtual Buddy.
6. Legal basis for processing
Under GDPR (Article 6), we process your personal data based on the following legal grounds:
- Contract performance (Art. 6(1)(b)): Processing necessary to deliver the service, including account management, storing your journal entries and goals, and processing payments
- Consent (Art. 6(1)(a)): Processing that requires your explicit opt-in, including sharing data with buddies, enabling Virtual Buddies, AI-powered personality test analysis, and push notifications. You can withdraw consent at any time through your account settings
- Legitimate interest (Art. 6(1)(f)): Processing that serves a reasonable business need, including security monitoring, fraud prevention, and platform integrity. We only process what is strictly necessary
7. Your rights
Under GDPR, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict processing of your data
- Object to processing based on legitimate interest
- Export your data in a portable format
- Withdraw consent at any time
To exercise these rights, contact us at privacy@beyondreality.vision.
8. Data retention
Upon receiving an account deletion request, we delete your personal data from Beyond Reality systems without undue delay. This includes your Firestore data, authentication records, and associated content.
Please note that our third-party processors may retain limited data per their own policies:
- OpenAI may retain abuse monitoring logs for up to 30 days
- Mollie may retain financial transaction records as required by law
9. International data transfers
Some of our third-party processors are based outside the European Economic Area (EEA). When your data is transferred outside the EEA, we ensure it is protected through appropriate safeguards:
- Google Firebase: Operates under Standard Contractual Clauses (SCCs) and participates in the EU-U.S. Data Privacy Framework (DPF)
- Anthropic: US-based. Data is sent to US servers for AI processing. Transfers are governed by Standard Contractual Clauses
- OpenAI: US-based (embeddings only). Participates in the EU-U.S. Data Privacy Framework
- Mollie: EU-based (Netherlands). Your payment data stays within the EEA
Standard Contractual Clauses (SCCs) are pre-approved legal contracts by the European Commission that require the receiving party to protect your data to EU standards. The Data Privacy Framework (DPF) is a US certification program recognized by the EU as providing adequate data protection.
10. Age restrictions
Beyond Reality is intended for users aged 16 and older. We do not knowingly collect personal data from users under 16. If we become aware that we have collected data from a user under 16, we will delete it promptly. If you believe a user under 16 has provided us with personal data, please contact us at privacy@beyondreality.vision.
11. Cookies
We use essential cookies for authentication and session management. We do not currently use analytics or tracking cookies.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification.
13. Contact
For privacy-related questions, contact us at privacy@beyondreality.vision.